SUSPICIOUS — 1091135556.pdf
SUSPICIOUS — 1091135556.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
410b219e4989b3474697267da4e51c8618c17aebe45aa2910e013a5be75e82b4 - SHA-1:
2ab0b65a818db3c79cfc0bc182f5c5716002f661 - MD5:
49e3bf428d173b29b18db038f988622b - ssdeep:
1536:NGFQjf9dz+2v09ob5Lo8Vw5lzWVcYHzVH:QFQjfr+289obhop5lYcop - TLSH:
T1B734BEF311B7DD8C7BCAEB0769BA1409A44EDB48213396A054D8776DC9BC2BD3E40A50 - Submitted as: 1091135556.pdf
- File type: pdf · Size: 54499 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/79f97188-a3db-463f-8188-06023eb2487e/62584107286.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=let+it+go+piano+notes+with+lyrics, https://cdn.shopify.com/s/files/1/0486/1765/2382/files/latagefixamaganumumufuje.pdf, https://cdn.shopify.com/s/files/1/0478/8990/7878/files/marion_county_sheriff_oregon_concealed_carry.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://gettraff.ru/strik?keyword=let+it+go+piano+notes+with+lyrics
- https://cdn.shopify.com/s/files/1/0486/1765/2382/files/latagefixamaganumumufuje.pdf
- https://cdn.shopify.com/s/files/1/0478/8990/7878/files/marion_county_sheriff_oregon_concealed_carry.pdf
- https://cdn.shopify.com/s/files/1/0496/3772/0215/files/gekupofizubanoligezogab.pdf
- https://cdn.shopify.com/s/files/1/0432/6955/4329/files/kupelegavefimuziva.pdf
- https://cdn.shopify.com/s/files/1/0435/4097/1674/files/jfk_bus_depot_phone_number.pdf
- https://uploads.strikinglycdn.com/files/79f97188-a3db-463f-8188-06023eb2487e/62584107286.pdf
- https://uploads.strikinglycdn.com/files/d361314c-41e4-4a9a-b77a-50ce83ae6f97/kejuvuzadasadijoxeduf.pdf
- https://uploads.strikinglycdn.com/files/bc14d134-0aae-4cf3-8942-055ad71a3bef/sepopazalini.pdf
- https://uploads.strikinglycdn.com/files/080b122d-74cd-4379-b210-66a6c23d5024/simosowelapiv.pdf
- https://uploads.strikinglycdn.com/files/92affb20-914c-403a-8cd3-2181f97ecbc5/60638093457.pdf
- https://uploads.strikinglycdn.com/files/d9282c42-8682-4652-96f9-7dcc66875247/kusedosonopewejite.pdf
- https://uploads.strikinglycdn.com/files/73fa1052-e75c-44da-9770-bc148d37a743/56966582278.pdf
- https://uploads.strikinglycdn.com/files/6fa4895f-88a7-49a4-9efc-1f9be550c4e5/6627046285.pdf
- https://uploads.strikinglycdn.com/files/6657583d-2181-4112-8d7f-1f5fb16fc37d/sikarojutegafakone.pdf
- https://uploads.strikinglycdn.com/files/9f1f4362-63d9-4bae-a4aa-37b88b5cb010/zuxexosulefujoke.pdf
- https://uploads.strikinglycdn.com/files/8a99b1db-1c3c-4055-abfa-520b90bc763c/70379714216.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report